Capture File Format Reference

Wireshark supports a variety of capture file formats.

Some of these formats are well-documented and therefore well-known, such as the PcapNg and Libpcap formats.

Other formats are added to Wireshark by reverse engineering, so the support of these formats is done through "sophisticated guesswork". This is the reason why support of these file types might be incomplete and inaccurate at some parts.

PcapNg captures (Wireshark native; readable by Libpcap 1.1.0 and later and thus by TcpDump and other tools that use it)

/libpcap captures (Wireshark native; readable and writable by Libpcap and thus by TcpDump and other tools that use it)